← Back to Vergilant

Privacy Policy

Last updated 27 July 2026

Vergilant records what your AI calls cost and whether they failed. It does not record what they said.

Who we are

Vergilant is operated by Arajen Kajanthirabalan ("we", "us"), based in Ontario, Canada. We are the organisation responsible for the personal information described here. For any privacy question or request, write to [email protected].

The short version

Your prompts and your model's replies pass through our proxy in memory and are forwarded to your AI provider. They are never written to disk, never written to a log, and never stored in our database. There is no column in our database that could hold them. What we keep is the envelope: which model, how long it took, how many tokens, what it cost, and whether it failed.

This is a deliberately narrow claim, and we would rather state it precisely than generously: request and response bodies do transit our servers. They have to, because we sit between you and your provider. They are not retained after the response is returned.

What we collect

Account information

Your email address, a bcrypt hash of your password (never the password itself), whether your email has been confirmed, your plan, and whether you have opted in to the monthly summary email. If you subscribe, we store the customer and subscription identifiers Stripe gives us. We never see or store your card details.

Request metadata

For each API call routed through our proxy we record: the project it belongs to, the time, the provider and model name, the HTTP status code, how long it took (split into our own processing time and your provider's), the number of input and output tokens, the estimated cost, and — when a call fails — the provider's error type. That list is exhaustive.

Alert settings

The Discord webhook URL or email address you ask us to send alerts to, and a record of the alerts we have sent, including the summary explaining why each one fired.

What we do not collect

  • The content of your prompts, or your model's responses.
  • Your AI provider's API key. It passes through the proxy to your provider and is not stored. We never log it.
  • Your IP address. We do not record it anywhere.
  • Your browser's user agent, or any device fingerprint.
  • Anything from advertising or analytics networks. Vergilant runs no third-party scripts, no analytics, and no trackers of any kind.

Cookies

Vergilant sets exactly one cookie: an HttpOnly session cookie that keeps you signed in. It is strictly necessary to operate the service, holds a random token rather than anything about you, and is deleted when you sign out. We use no advertising, analytics, or tracking cookies, which is why you are not being asked to accept any.

Why we are allowed to use it

Under Canadian privacy law (PIPEDA) we rely on your consent, which you give by creating an account and by configuring the alerts you want to receive. You may withdraw it at any time by deleting your account.

If you are in the UK or the European Economic Area, the UK GDPR and GDPR also apply to us. There, our lawful bases are performance of a contract (running the service you signed up for) and our legitimate interest in keeping the service secure and working. Where we rely on consent — the optional monthly summary email — you can withdraw it in Account settings without losing anything else.

How long we keep it

Request metadata is deleted automatically once it passes your plan's retention window: 7 days on the Free plan and 90 days on Pro. This is enforced by a scheduled job, not by request.

Account information, projects and alert settings are kept until you delete them. Deleting your account removes your account record, your projects, your alert rules and channels, and all request metadata belonging to them. That deletion is immediate and permanent — there is no soft-delete and no recovery window, so export anything you want to keep first.

Who else touches it

We do not sell personal information, and we do not share it for advertising. We use the following service providers to run Vergilant, each with access only to what their function requires:

  • Fly.io — application hosting (United States).
  • Supabase — the database holding accounts and request metadata (United States).
  • Cloudflare — hosting and delivery of the web interface.
  • Stripe — subscription payments. Stripe handles card details directly; we never receive them.
  • Resend — delivery of account and alert emails.

We will also disclose information where the law requires it, and we will tell you when we are permitted to.

Where it is stored

Vergilant's servers and database are located in the United States. If you are outside the United States, your information is transferred there and is subject to the laws of that country, including lawful access requests by US authorities. We are telling you this because Canadian privacy law requires that transfers across borders be disclosed, and because you should know it regardless.

For users in the UK or EEA, these transfers are made under the European Commission's Standard Contractual Clauses (and the UK Addendum), which our providers offer.

Your rights

You can, at any time:

  • See what we hold. Your dashboard shows your request metadata directly. For anything else, ask us.
  • Correct it. Change your email address and password in Account settings.
  • Delete it. Deleting your account in Account settings erases everything described above, without needing to contact us.
  • Withdraw consent to the monthly summary, or to the service as a whole by closing your account.

UK and EEA users additionally have rights to data portability, to restrict or object to processing, and not to be subject to decisions made solely by automated means. Vergilant makes no automated decisions that produce legal effects about you.

Write to [email protected] to exercise any of these. We will respond within 30 days.

Security

All traffic is served over HTTPS. Passwords are stored as bcrypt hashes and cannot be read back by us or anyone else. Session cookies are HttpOnly and Secure, so page scripts cannot read them. Project keys are shown to you and stored so that incoming requests can be matched to your account.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the Office of the Privacy Commissioner of Canada as required.

Children

Vergilant is a tool for software developers and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.

Complaints

If we have not resolved a privacy concern to your satisfaction, you may complain to the Office of the Privacy Commissioner of Canada. UK and EEA users may complain to their own supervisory authority — in the UK, the Information Commissioner's Office.

Changes

If we change this policy we will update the date above, and for any change that materially affects how we handle your information we will email you before it takes effect.

Privacy PolicyTerms of Service

© 2026 Arajen Kajanthirabalan